Grafana

Grafana

84 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 22.03.2021 15:15:14
  • Zuletzt bearbeitet 21.11.2024 05:59:10

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabl...

  • EPSS 0.28%
  • Veröffentlicht 22.03.2021 14:15:14
  • Zuletzt bearbeitet 21.11.2024 05:58:55

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

  • EPSS 0.27%
  • Veröffentlicht 22.03.2021 14:15:14
  • Zuletzt bearbeitet 21.11.2024 05:59:10

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing ...

  • EPSS 81.14%
  • Veröffentlicht 18.03.2021 20:15:13
  • Zuletzt bearbeitet 21.11.2024 05:57:50

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

Exploit
  • EPSS 11.09%
  • Veröffentlicht 21.12.2020 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:21:55

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

  • EPSS 0.36%
  • Veröffentlicht 28.10.2020 14:15:12
  • Zuletzt bearbeitet 21.11.2024 05:14:34

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

Exploit
  • EPSS 37.44%
  • Veröffentlicht 28.08.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:50

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

  • EPSS 74.77%
  • Veröffentlicht 27.07.2020 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:56:48

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

Exploit
  • EPSS 93.25%
  • Veröffentlicht 03.06.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:01:08

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can b...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 02.06.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 03:56:15

Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.